Junglewise Threat Intelligence

CVE-2026-43169: Linux Kernel denial of service in drm/buddy allocator

CVE-2026-43169 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's graphics memory management component could allow a local user to crash the system. The issue occurs when the system attempts to allocate large blocks of video memory (VRAM) and fails to properly validate the requested size after rounding it up. This can lead to a kernel panic, resulting in a complete denial of service for the affected machine.

Technical details

A vulnerability exists in the drm_buddy.c component of the Linux kernel's Direct Rendering Manager (DRM) subsystem. When DRM_BUDDY_CONTIGUOUS_ALLOCATION is requested, the allocator rounds the size up to the next power-of-two; similarly, non-contiguous allocations with large min_block_size are aligned up. If these rounding operations result in a size exceeding the total available memory (mm->size), the kernel triggers a BUG_ON(order > mm->max_order) during the allocation loop. A local attacker can exploit this by requesting specific large memory allocations to crash the host. The fix introduces validation checks to return -EINVAL or use a fallback path instead of triggering the kernel panic.

Affected products

  • Linux Linux Kernel 6.7 to 6.12.74, 6.13 to 6.18.15, 6.19 to 6.19.5

Timeline

  • 2026-01-08: other: Patch authored
  • 2026-05-06: disclosed: CVE published
  • 2026-05-06: advisory

References

Related threats